General Data Protection Regulation (GDPR) Compliance
Last updated: June 29, 2025
Grivexlogicxy ("we," "our," or "us") is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This policy explains how we collect, use, store, and protect your personal information.
1. Data Controller
Grivexlogicxy is the data controller responsible for your personal data. You can contact us at:
- Address: ul. PŁASZOWSKA 21, 30-713 KRAKÓW, Polska
- Email: [email protected]
- Phone: +48722083946
2. Personal Data We Collect
We collect and process the following categories of personal data:
2.1 Information You Provide
- Identity data: name, username, title
- Contact data: email address, telephone number, physical address
- Account data: login credentials, preferences, settings
- Professional data: career goals, skill level, educational background
- Payment data: billing information, transaction history
- Communication data: messages, feedback, survey responses
2.2 Information We Collect Automatically
- Technical data: IP address, browser type, device information, operating system
- Usage data: pages visited, features used, time spent, interaction patterns
- Location data: general geographic location based on IP address
- Performance data: session recordings, error logs, analytics data
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract performance: Processing necessary to provide mentorship services you requested
- Consent: You have given clear consent for specific processing purposes
- Legitimate interests: Processing necessary for our legitimate business operations, provided your rights do not override these interests
- Legal obligation: Processing required to comply with applicable laws and regulations
4. How We Use Your Personal Data
We use your personal data for the following purposes:
- Delivering mentorship services and educational content
- Creating and managing your account
- Matching you with appropriate mentors
- Processing payments and maintaining financial records
- Communicating with you about services, updates, and support
- Improving our platform and user experience
- Analyzing usage patterns and service effectiveness
- Ensuring platform security and preventing fraud
- Complying with legal and regulatory requirements
- Marketing our services where you have consented
5. Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
5.1 Service Providers
- Cloud hosting and infrastructure providers
- Payment processors and financial institutions
- Communication and email service providers
- Analytics and performance monitoring tools
- Customer support platforms
5.2 Mentors
We share relevant information with assigned mentors to facilitate the mentorship relationship, including your name, contact details, professional background, and learning goals.
5.3 Legal Requirements
We may disclose your data when required by law, court order, or governmental authority, or to protect our rights, property, or safety.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection
- Binding Corporate Rules for intra-group transfers
- Appropriate technical and organizational security measures
7. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Active account data: retained while your account remains active
- Transaction records: retained for 7 years for accounting and tax purposes
- Communication records: retained for 3 years after the last interaction
- Marketing data: retained until you withdraw consent or for 2 years of inactivity
- Legal claims data: retained for applicable statute of limitations periods
After the retention period expires, we securely delete or anonymize your personal data.
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
8.1 Right of Access
You can request confirmation of whether we process your personal data and obtain a copy of that data.
8.2 Right to Rectification
You can request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure
You can request deletion of your personal data when:
- It is no longer necessary for the purposes collected
- You withdraw consent and no other legal basis exists
- You object to processing and no overriding legitimate grounds exist
- The data was unlawfully processed
- Erasure is required for legal compliance
8.4 Right to Restriction of Processing
You can request limitation of processing when:
- You contest the accuracy of the data
- Processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification
8.5 Right to Data Portability
You can receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
8.6 Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes at any time.
8.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of prior processing.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority if you believe we have violated your data protection rights.
9. Exercising Your Rights
To exercise any of your rights, please contact us at:
- Email: [email protected]
- Phone: +48722083946
- Mail: ul. PŁASZOWSKA 21, 30-713 KRAKÓW, Polska
We will respond to your request within 30 days. If we require additional time, we will inform you of the extension and the reasons for the delay.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection practices
- Incident response and breach notification procedures
- Regular data backups and disaster recovery plans
- Secure development practices and code reviews
11. Automated Decision-Making
We may use automated processing to:
- Match clients with suitable mentors based on criteria and preferences
- Recommend relevant educational content and resources
- Detect fraudulent activity and security threats
You have the right to request human intervention, express your point of view, and contest automated decisions that produce legal effects or similarly significantly affect you.
12. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. You can control cookie preferences through your browser settings. For detailed information, please refer to our Cookie Policy.
13. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
14. Changes to This Policy
We may update this GDPR policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the "Last updated" date
- Sending email notifications for significant changes
- Requesting renewed consent where required
We encourage you to review this policy regularly to stay informed about how we protect your data.
15. Data Protection Officer
For questions about this policy or our data protection practices, you can contact our data protection team at [email protected].
16. Contact Information
If you have questions, concerns, or requests regarding this GDPR policy or your personal data, please contact us:
- Grivexlogicxy
- ul. PŁASZOWSKA 21, 30-713 KRAKÓW, Polska
- Email: [email protected]
- Phone: +48722083946
Summary of Key Points
| Topic | Summary |
|---|---|
| Data Controller | Grivexlogicxy, ul. PŁASZOWSKA 21, 30-713 KRAKÓW, Polska |
| Data Collected | Identity, contact, account, professional, payment, technical, and usage data |
| Legal Basis | Contract performance, consent, legitimate interests, legal obligation |
| Primary Uses | Service delivery, account management, mentor matching, communications, improvements |
| Data Sharing | Service providers, mentors, legal authorities when required |
| Your Rights | Access, rectification, erasure, restriction, portability, objection, complaint |
| Retention | Duration necessary for purpose, up to 7 years for financial records |
| Security | Encryption, access controls, regular assessments, employee training |
| Contact | [email protected] or +48722083946 |
